Specific Objectives Strategies/ Actions Strategic Goal – 1: 3.4.1 Specific Objective 1: Identify and protect the Critical Information Infrastructure of Malawi Deliverables/ Outputs Lead Implementing Agency and Support Time Frame Key Performance Indicators Possible Funding Sources and Mechanisms Identify and manage the Critical Information Infrastructure of Malawi 3.4.1.1 Establish a national CII register National Register CII 3.4.1.2 Develop a National CII Governance Framework which provides details on CII protection procedures and processes National CII Governance Framework 3.4.1.3 Establish a National Risk Register and regulations and/or guidelines that promote continuous risk assessment and management across CIIs in Malawi Risk assessment and management guidelines for CIIs 3.4.1.4 Establish mandatory equipment specifications, Mandatory guidelines, regulations, security requirements, procedures relating to the management of risks by CIIS CII Minimum security standards and procedures including security audits, equipment specifications, SOPS, Access MACRA/Malawi CERT/Ministry of ICT Within 6 months and continuous Publication National Register of CII MACRA/Malawi CERT MACRA/Malawi CERT Within 6 months and continuous Publication of National CII Governance Framework which provides details on CII protection procedures and processes MACRA/Malawi CERT Within 6 months and continuous Frequency of Risk assessment exercises MACRA/Malawi CERT Malawi CII/ Ministry of ICT National Register MACRA/Malawi CERT Malawi CII/ Ministry of ICT Risk Ministry of ICT MACRA/MALAWI CERT Malawi CII Frequency of update to National Risk Register Within 12 months and continuous Extent of implementation of standards, procedures, guidelines, ,specifications, Equipment Specifications, SOPS, Access Ministry of ICT MACRA/MALAWI CERT Page | 34

Select target paragraph3